﻿using System;
using System.Data;
using System.Configuration;
using System.Collections;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using System.Data.OleDb;
using qiupeng.Public;
using System.IO;

public partial class _Default : System.Web.UI.Page 
{
    Db List = new Db();
    protected void Page_Load(object sender, EventArgs e)
    {

    }

    public void KaoQin()
    {



    }


    protected void ImageButton1_Click(object sender, ImageClickEventArgs e)
    {
        string str = FormsAuthentication.HashPasswordForStoringInConfigFile(this.Password.Text, "MD5");
        string sql = "select * from qp_hr_username where Username='" + this.List.GetFormatStr(this.Username.Text) + "' and Password='" + str + "' ";
        OleDbDataReader list = this.List.GetList(sql);
        if (list.Read())
        {
            string str3 = "select * from qp_hr_username where Username='" + this.List.GetFormatStr(this.Username.Text) + "' and Password='" + str + "'and Iflogin='是'  ";
            OleDbDataReader reader2 = this.List.GetList(str3);
            if (reader2.Read())
            {
                this.Session["userName"] = list["Username"].ToString();
                this.Session["realname"] = list["XingMing"].ToString();
                this.Session["perstr"] = list["ResponQx"].ToString();
                list["bmqx"].ToString();
                this.Session["bmqxa"] = (list["bmqx"].ToString() == "") ? "100000" : list["bmqx"].ToString();
                this.Session["StaffId"] = list["StaffId"].ToString();
                this.Session["StaffNumer"] = list["StaffNumer"].ToString();
                this.Session["BuMenID"] = list["BuMenID"].ToString();
                this.Session["ResponseRemark"] = list["ResponRemark"].ToString();
                int num = new Random().Next(0, 0x3e8);
                this.Session[this.Session["userName"].ToString()] = num.ToString();
                base.Application[this.Session["userName"].ToString()] = num;
                this.List.InsertLog("登陆系统[" + this.Session["realname"] + "]", "登陆系统");
                base.Response.Redirect("main.aspx");
            }
            else
            {
                base.Response.Write("<script language=javascript>alert('此帐号不允许登陆！');</script>");
                return;
            }
            reader2.Close();
        }
        else
        {
            string str4 = "select * from qp_hr_username where staffnumer in (select gonghao from qp_hr_Staff where shenfen='" + this.List.GetFormatStr(this.Username.Text) + "') and Password='" + str + "' ";
            OleDbDataReader reader3 = this.List.GetList(str4);
            if (reader3.Read())
            {
                this.Session["userName"] = reader3["Username"].ToString();
                this.Session["realname"] = reader3["XingMing"].ToString();
                this.Session["perstr"] = reader3["ResponQx"].ToString();
                reader3["bmqx"].ToString();
                this.Session["bmqxa"] = (reader3["bmqx"].ToString() == "") ? "100000" : reader3["bmqx"].ToString();
                this.Session["StaffId"] = reader3["StaffId"].ToString();
                this.Session["StaffNumer"] = reader3["StaffNumer"].ToString();
                this.Session["BuMenID"] = reader3["BuMenID"].ToString();
                this.Session["ResponseRemark"] = reader3["ResponRemark"].ToString();
                int num2 = new Random().Next(0, 0x3e8);
                this.Session[this.Session["userName"].ToString()] = num2.ToString();
                base.Application[this.Session["userName"].ToString()] = num2;
                this.List.InsertLog("登陆系统[" + this.Session["realname"] + "]", "登陆系统");
                base.Response.Redirect("main.aspx");
            }
            else
            {
                base.Response.Write("<script language=javascript>alert('用户名或密码错误！请联系您所交流的客服QQ或电话！');</script>");
                return;
            }
        }
        list.Close();

    }

    //public void InsertLog(string Name, string MkName)
    //{
    //    string sql_insert_log = "insert into qp_hr_SystemLog (Name,MkName,Username,Realname,Nowtimes,Ip,Unit,UnitId,QxString) values ('" + Name + "','" + MkName + "','" + this.Session["username"] + "','" + this.Session["realname"] + "','" + System.DateTime.Now.ToString() + "','" + Page.Request.UserHostAddress + "','" + this.Session["QxString"] + "')";
    //    List.ExeSql(sql_insert_log);
    //}
}
